Live data from Hacker News

A billion medical images are exposed online

techcrunch.com

161–170 of 201 posts

Re: A billion medical images are exposed online

#161
Physician here (neuroradiologist) and after working at several hospitals in the US and abroad, let me be really clear about this:

1) I have never seen a health care organization ANYWHERE where the physicians determine the IT policy (including and especially the IT security policy).

2) Universally, healthcare organizations use the bloated garbage that gets passed off as EMRs and affiliated garbage software. None of this is up to physicians. It's up to the administrative and bureaucratic parasites that have infested healthcare at every level and based largely (I assume) on crony relationships, because it's certainly not based on competence.

3)Healthcare IT is the most abysmal software anyone anywhere has ever devised to perform any task. Systems like EPIC are bloated, barely functional trash that systems have wasted billions of dollars on. The various components of departmental IT do not co-ordinate with one another, crash on a daily basis, are not fit for purpose and would embarrass engineers in any other industry.

It comes as no surprise that security for these systems is piss-poor, just like everything else about these systems. Blaming doctors for this administrative mess, whilst not unexpected, is disingenuous at best (of course this is what healthcare administration excel at - making a mess and blaming physicians).

Re: A billion medical images are exposed online

#162

An odd line from the article, wherein it states that security researchers don’t blame vendors, but the physicians and hospitals that fail to properly secure the software. I have never, in all my years of working in healthcare, seen a hospital or physicians office directly install and manage PACS. They pay a third-party - usually the vendor - to install, configure, and walk them through it. Maybe a behemoth system lik…

I’ve been the IT vendor in this scenario. While I’m sure there are plenty of inept vendors not doing their part to ensure the systems they implement are secure, a big part of it is doctors and their work culture. Many doctors see themselves as too important to deal with security. They have an attitude of “I went to school for medicine, not computers! How dare you ask me to use a computer.” They are not only technolog…

The example you site is so egregious (and unlikely) that there isn't a hospital in the US today where a physician who did anything remotely close to what you describe wouldn't immediately be fired (appropriately I might add).

The bigger issue is how did the vendor or IT department responsible for the network allow routine internet access to interface with critical healthcare or financial infrastructure? (You don't have to be looking at porn to be on the wrong side of a phishing scam).

Clearly you've had bad experiences with (some) doctors - generalizing that experience and extrapolating it to the issue of IT security is deeply flawed reasoning.

Re: A billion medical images are exposed online

#163
post #159
post #157

Earlier quoted context omitted.

So the doctor has to ensure security in addition of treating patient? Why do we need security professional then ?

Yes, everyone has to participate in ensuring security; how completely divorced from reality do you have to be to think otherwise. And we need security professionals to remind everyone that security is important and we all have to be part of ensuring it.

Sure but if it become annoying then most people, including me will choose convinience over security every time.

That's where I critize security professional. They often disregard this end user pain.

You have to find frictionless solution and shouldn't impact their productivity.

Re: A billion medical images are exposed online

#164
post #163
post #159

Earlier quoted context omitted.

Yes, everyone has to participate in ensuring security; how completely divorced from reality do you have to be to think otherwise. And we need security professionals to remind everyone that security is important and we all have to be part of ensuring it.

Sure but if it become annoying then most people, including me will choose convinience over security every time. That's where I critize security professional. They often disregard this end user pain. You have to find frictionless solution and shouldn't impact their productivity.

It is your responsibility to participate in the security of your customer's information. It is your fault if you "choose convenience over security". It is not anyone else's fault.

Ask yourself how you would feel if your bank just let someone access your account and steal your money. Would you forgive them if the bank said "well it would have been really annoying to have to check the person's identity before letting them take the money, so we chose convenience over security"? Of course not.

Security professionals are there to guide you and make security tools easier and less intrusive for you to use (and believe me, they want to make it easier for you, if only for the entirely self-serving reason of reducing the amounts of complaints they get), but even if the security tools are hard to use, it is your responsibility to still use them. You are not doing your job if you disregard them, and "it's annoying" is absolutely, 1000% not an excuse for potentially exposing the sensitive information of every one of your customers.

Re: A billion medical images are exposed online

#165

Earlier quoted context omitted.

Have you worked with doctor's? When I did I'd routinely sit in a room with 10-25 people and wait for hours on a doctor to show up to a meeting they'd schedule onlu to be told by a secretary he was busy. Everyone I know who has worked with doctor's has similar stories. This hasn't happened to me with any other position in any other organization, including vice presidents of Fortune 500 companies.

I'm not claiming that doctors are interchangeable with other careers. Doctors often have higher priorities that can absolutely intrude at any time: An emergent medical situation is far more important than a meeting about document retention, for instance. For that VP, or CEO for that matter, those meetings are a major priority of their job. Instead I was pointing out that there are many fields where people resist IT-s…

Sorry I didn't mean to make the argument that doctor's are unique in pushing against IT policies.

But they do push back uniquely hard. My experience and almost everyone I've talked to in Medical IT have had the same experience. Have you had a different one?

Re: A billion medical images are exposed online

#166
post #163

Earlier quoted context omitted.

Sure but if it become annoying then most people, including me will choose convinience over security every time. That's where I critize security professional. They often disregard this end user pain. You have to find frictionless solution and shouldn't impact their productivity.

It is your responsibility to participate in the security of your customer's information. It is your fault if you "choose convenience over security". It is not anyone else's fault. Ask yourself how you would feel if your bank just let someone access your account and steal your money. Would you forgive them if the bank said "well it would have been really annoying to have to check the person's identity before letting t…

Trying to shift security to end user wouldn't improve security. Most people value convenience over security.

Then the bank is not doing a good job. Its the bank responsibility to secure my account. How they do it is up to them . I don't really care what method they use as long as from my perspective its frictionless and not annoying.

If you make security tools that is hard to use, then you are not doing a good job, be prepare for push back and consequently less secure environment.

Re: A billion medical images are exposed online

#167

If this article is correct, it's such a huge problem that health systems are likely to hesitate to take steps toward basic imaging security, because they won't know what to do first.

I think what to do first is really quite simple: Do not let back-end servers face the internet.

Re: A billion medical images are exposed online

#169

Could this data be anonymized and open-sourced for training diagnostic algorithms? It’s hard to put the genie back in the bottle so why not at least make some use of the images?

Is it possible? The metadata is easy to anonymize. Uniquely identifying features shown in the images (scars, etc)? Not without destroying them.

How much is the data worth for machine learning if you do not have access to the interpretation (and annotations) for the data? That is the hard part.

But. Is it ethical or even legal to do so without patient consent? No (at least not in my country).

Re: A billion medical images are exposed online

#170
post #125
post #119

Earlier quoted context omitted.

Growing complexity. Struggling scalability. Overspecialization. Balkanization. Failures of accountability. OP’s firsthand observation on the awful state of programmer-produced medical software, the original linked article, and notoriously lethal software disasters such as Therac-25 provide frightening cases in point. These things are not accidents. Programmers who only know how to program are as much use as managers…

I've never seen a programmer produced medical system. Do you realize these systems are designed by respected doctors and product managers? They tell the programmers exactly what to do. When something vague comes up the product manager talks to his stakeholders and decides how to proceed. When the project is done the doctor/project manager group go over everything and make changes. They decide things like how it looks…

“Do you realize these systems are designed by respected doctors and product managers? They tell the programmers exactly what to do.”

And here, in a nutshell, is EVERYTHING wrong in modern software development.

Doctors are NOT programmers. If they were, they wouldn’t need to hire programmers: they’d write the solution themselves!

Doctors are the domain experts. They understand medicine, and procedures in its current practice, and the reasons why things are done the way they are.

Conversely, the programmers’ job is not to write code. Any monkey can do that. It is to learn the problem space; to extract from the domain experts sufficient knowledge and insight to understand those procedures and why they are as they are for themselves. And then, starting from there, synthesize a new solution that does it all better.

And the PMs’ job is to mediate that learning process; to ensure both parties understand these objectives and keep them on track; and otherwise keep the hell out their way.

Whereas current industry practice is for programmers to sit with their thumbs up their asses, expecting others to tell them exactly what to do so they don’t have to learn, while PMs micromanage all the minutae so never have to take responsibility for the house itself burning down.

This is like civilian government telling military how to fight their war (e.g. Iraq War, 2003…2???), or the “Official European Joke” about Heaven and Hell. And not only are in the Hell part, the Programmers and PMs—who are supposed to be the highly-paid professional problem solvers here—really seem to believe that this hell we’re in is “How Things Should Be”; and thus only serve to multiply those problems instead.

..

FFS, I eventually got so sick of it all that I taught myself how to program (ugh), just so I wouldn’t have to go through all these useless spanners any more.

And, it pains me to say, software development is the first (and still only) career in my half-century of life where I’ve NOT felt crippled with Impostor Syndrome. Because the impostor, I realized, was everyone else.

Post reply on HN